command-line-murders/i-0e16957c32496d28e
by SadServersMore by SadServers
sudo: 3 incorrect password attempts admin@i-0ade0a697ccc4e8f9:/$ cd /usr/ bin/ include/ lib32/ libexec/ local/ share/ games/ lib/ lib64/ libx32/ sbin/ src/ admin@i-0ade0a697ccc4e8f9:/$ cd /home/admin/ admin@i-0ade0a697ccc4e8f9:~$ ls agent webserver.py admin@i-0ade0a697ccc4e8f9:~$ ls agent/ check.sh sadagent sadagent.txt admin@i-0ade0a697ccc4e8f9:~$ ls agent/sadagent agent/sadagent admin@i-0ade0a697ccc4e8f9:~$ less agent/sadagent sadagent sadagent.txt admin@i-0ade0a697ccc4e8f9:~$ less agent/sadagent.txt admin@i-0ade0a697ccc4e8f9:~$ less agent/sadagent.txt
paris/i-0ade0a697ccc4e8f9 06:56
by SadServersJan 02 13:55:10 i-05560191eefbc7318 dhclient[471]: XMT: Solicit on ens5, intervaJan 02 13:55:16 i-05560191eefbc7318 python3[583]: 127.0.0.1 - - [02/Jan/2024 13:Jan 02 13:56:19 i-05560191eefbc7318 systemd[1]: Started Hammer Time. Jan 02 13:56:20 i-05560191eefbc7318 systemd[1]: mc.service: Succeeded. Jan 02 13:56:31 i-05560191eefbc7318 su[844]: pam_unix(su:auth): authentication fJan 02 13:56:33 i-05560191eefbc7318 su[844]: FAILED SU (to root) admin on pts/1 Jan 02 13:56:58 i-05560191eefbc7318 dhclient[471]: XMT: Solicit on ens5, intervaJan 02 13:57:07 i-05560191eefbc7318 python3[583]: 127.0.0.1 - - [02/Jan/2024 13:Jan 02 13:57:14 i-05560191eefbc7318 python3[583]: 127.0.0.1 - - [02/Jan/2024 13:Jan 02 13:57:17 i-05560191eefbc7318 systemd[1]: Started Hammer Time. Jan 02 13:57:18 i-05560191eefbc7318 systemd[1]: mc.service: Succeeded. Jan 02 13:58:02 i-05560191eefbc7318 systemd[1]: Started Hammer Time. Jan 02 13:58:03 i-05560191eefbc7318 systemd[1]: mc.service: Succeeded. ^[[6~^[[6~^[[6~^C admin@i-05560191eefbc7318:~$ cd
paris/i-05560191eefbc7318 04:19
by SadServers> GET / HTTP/1.1 > Host: localhost:5000 > User-Agent: curl/7.74.0 > Accept: */* > * Mark bundle as not supporting multiuse < HTTP/1.1 200 OK < Server: Werkzeug/2.3.7 Python/3.9.2 < Date: Wed, 04 Oct 2023 19:07:43 GMT < Content-Type: text/html; charset=utf-8 < Content-Length: 12 < Connection: close < * Closing connection 0 Unauthorizedadmin@i-09e85561fc3517875:~$ curl -Lv http://localhost:5000